LWN.net Logo

moodle: multiple vulnerabilities

Package(s):moodle CVE #(s):CVE-2012-2353 CVE-2012-2354 CVE-2012-2355 CVE-2012-2356 CVE-2012-2357 CVE-2012-2358 CVE-2012-2359 CVE-2012-2360 CVE-2012-2361 CVE-2012-2362 CVE-2012-2363 CVE-2012-2364 CVE-2012-2365 CVE-2012-2366 CVE-2012-2367
Created:June 1, 2012 Updated:August 2, 2012
Description:

From the Fedora advisory:

Update Information:

CVE-2012-2353 MSA-12-0024: Hidden information access issue

CVE-2012-2354 MSA-12-0025: Personal communication access issue

CVE-2012-2355 MSA-12-0026: Quiz capability issue

CVE-2012-2356 MSA-12-0027: Question bank capability issues

CVE-2012-2357 MSA-12-0028: Insecure authentication issue

CVE-2012-2358 MSA-12-0029: Information editing access issue

CVE-2012-2359 MSA-12-0030: Capability manipulation issue

CVE-2012-2360 MSA-12-0031: Cross-site scripting vulnerability in Wiki

CVE-2012-2361 MSA-12-0032: Cross-site scripting vulnerability in Web services

CVE-2012-2362 MSA-12-0033: Cross-site scripting vulnerability in Blog

CVE-2012-2363 MSA-12-0034: Potential SQL injection issue

CVE-2012-2364 MSA-12-0035: Cross-site scripting vulnerability in "download all"

CVE-2012-2365 MSA-12-0036: Cross-site scripting vulnerability in category identifier

CVE-2012-2366 MSA-12-0037: Write access issue in Database activity module

CVE-2012-2367 MSA-12-0038: Calendar event write permission issue

Correct CAS unbundling.

Drop bundled language packs.

New upstreams, multiple vulnerabilities.

Alerts:
Fedora FEDORA-2012-8284 2012-06-01
Fedora FEDORA-2012-8325 2012-06-02
Fedora FEDORA-2012-8365 2012-06-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds